7.5

CVE-2014-1883

Exploit
Adobe PhoneGap before 2.6.0 on Android uses the shouldOverrideUrlLoading callback instead of the proper shouldInterceptRequest callback, which allows remote attackers to bypass intended device-resource restrictions via content that is accessed (1) in an IFRAME element or (2) with the XMLHttpRequest method by a crafted application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobePhonegap Version <= 2.5.0
AdobePhonegap Version2.0.0
AdobePhonegap Version2.0.0 Updaterc1
AdobePhonegap Version2.1.0
AdobePhonegap Version2.2.0
AdobePhonegap Version2.2.0 Updaterc1
AdobePhonegap Version2.2.0 Updaterc2
AdobePhonegap Version2.3.0
AdobePhonegap Version2.3.0 Updaterc1
AdobePhonegap Version2.3.0 Updaterc2
AdobePhonegap Version2.4.0
AdobePhonegap Version2.4.0 Updaterc1
AdobePhonegap Version2.5.0 Updaterc1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.32% 0.78
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P